# PR Format

## Title Format

```
deps: [type] update <group-name>
```

Types:
- `security` - Vulnerability fixes
- `patch` - Patch version updates
- `minor` - Minor version updates
- `major` - Major version updates

Examples:
- `deps: security fix 2 vulnerabilities in vitest`
- `deps: patch update 8 packages`
- `deps: major update react 18 → 19`

## Body Template

```markdown
## Summary
<1-2 sentence description of what's being updated and why>

## Changes

| Package | Current | Updated | Type |
|---------|---------|---------|------|
| pkg-a   | 1.0.0   | 1.1.0   | minor |
| pkg-b   | 2.3.4   | 2.3.5   | patch |

## Changelog Highlights

### pkg-a (1.0.0 → 1.1.0)
- Added: New feature X
- Fixed: Bug in Y

## Test Results

- [x] Tests passed
- [x] Type check passed
- [x] Build succeeded

## Risk Assessment

**Overall Risk: Low/Medium/High**

<Brief explanation of any concerns or migration notes>

---
Generated by update-dependencies skill
```

## Example: Security Update

```markdown
## Summary
Fixes 2 moderate severity vulnerabilities.

## Changes

| Package | Current | Updated | Type |
|---------|---------|---------|------|
| vitest  | 2.1.0   | 2.1.8   | patch |
| vite    | 5.4.0   | 5.4.11  | patch |

## Changelog Highlights

### vitest (2.1.0 → 2.1.8)
- Fixed: Prototype pollution vulnerability (CVE-2024-XXXX)

### vite (5.4.0 → 5.4.11)
- Fixed: XSS vulnerability in dev server

## Test Results

- [x] Tests passed
- [x] Type check passed

## Risk Assessment

**Overall Risk: Low**

Patch updates with security fixes. No breaking changes.

---
Generated by update-dependencies skill
```

## Example: Ecosystem Batch

```markdown
## Summary
Updates all Radix UI components to latest versions.

## Changes

| Package | Current | Updated | Type |
|---------|---------|---------|------|
| @radix-ui/react-checkbox | 1.0.4 | 1.1.0 | minor |
| @radix-ui/react-dialog | 1.0.5 | 1.1.0 | minor |
| @radix-ui/react-tooltip | 1.0.7 | 1.1.0 | minor |

## Changelog Highlights

### @radix-ui/react-* (1.0.x → 1.1.0)
- Added: Improved accessibility defaults
- Added: New `forceMount` prop
- Fixed: Focus management in modals

## Test Results

- [x] Tests passed
- [x] Type check passed

## Risk Assessment

**Overall Risk: Low**

Minor updates with backwards-compatible additions.

---
Generated by update-dependencies skill
```

## Creating PR with Heredoc

```bash
gh pr create --title "deps: patch update 8 packages" --body "$(cat <<'EOF'
## Summary
Batch update of low-risk patch dependencies.

## Changes
...

---
Generated by update-dependencies skill
EOF
)"
```
